{"id":"CVE-2023-50263","aliases":["GHSA-75mc-3pjc-727q","PYSEC-2023-286"],"title":"Unauthenticated db-file-storage views","summary":"Unauthenticated db-file-storage views","severity":"low","cvss":3.7,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","vendor":"nautobot","product":"nautobot","ecosystem":"pip","affected":["nautobot >= 1.1.0, < 1.6.7","nautobot >= 2.0.0, < 2.0.6"],"patched":["nautobot 1.6.7","nautobot 2.0.6"],"published":"2023-12-13","updated":"2026-09-10","sourceUpdated":"2026-09-10T03:49:59.415839617Z","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-75mc-3pjc-727q","references":[{"url":"https://github.com/nautobot/nautobot/security/advisories/GHSA-75mc-3pjc-727q"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2023-50263"},{"url":"https://github.com/nautobot/nautobot/pull/4959"},{"url":"https://github.com/nautobot/nautobot/pull/4964"},{"url":"https://github.com/nautobot/nautobot/commit/458280c359a4833a20da294eaf4b8d55edc91cee"},{"url":"https://github.com/nautobot/nautobot/commit/5e2ba9e8ac0840b1c44eb1a8ea3c0bd2c68e4f80"},{"url":"https://github.com/nautobot/nautobot/commit/7c4cf3137f45f1541f09f2f6a7f8850cd3a2eaee"},{"url":"https://github.com/nautobot/nautobot"},{"url":"https://github.com/pypa/advisory-database/tree/main/vulns/nautobot/PYSEC-2023-286.yaml"},{"url":"https://github.com/victor-o-silva/db_file_storage/blob/master/db_file_storage/views.py"}],"tags":["osv","pip"],"epss":0.00754,"epssPercentile":0.53602,"ingestedAt":"2026-09-12T03:13:01.670Z","slug":"CVE-2023-50263","body":"## Overview\n\n### Impact\n\n In Nautobot 1.x and 2.0.x, the URLs `/files/get/?name=...` and `/files/download/?name=...` are used to provide admin access to files that have been uploaded as part of a run request for a Job that has FileVar inputs. Under normal operation these files are ephemeral and are deleted once the Job in question runs. \n\nIt was reported by @kircheneer that in the default implementation used in Nautobot, as provided by `django-db-file-storage`, these URLs do not by default require any user authentication to access; they should instead be restricted to only users who have permissions to view Nautobot's `FileProxy` model instances.\n\nNote that no URL mechanism is provided for listing or traversal of the available file `name` values, so in practice an unauthenticated user would have to guess names to discover arbitrary files for download, but if a user knows the file name/path value, they can access it without authenticating, so we are considering this a vulnerability.\n\n### Patches\n\nFixes will be included in Nautobot 1.6.7 and Nautobot 2.0.6.\n\n### Workarounds\n\nNo workaround other than applying the patches included in https://github.com/nautobot/nautobot/pull/4959/files (2.0.x) or https://github.com/nautobot/nautobot/pull/4964/files (1.6.x)\n\n### References\n\n- https://github.com/victor-o-silva/db_file_storage/blob/master/db_file_storage/views.py\n\n## Affected packages\n\n- `nautobot >= 1.1.0, < 1.6.7`\n- `nautobot >= 2.0.0, < 2.0.6`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `nautobot 1.6.7`\n- `nautobot 2.0.6`","depth":"sunlit","depthScore":21,"depthScoreParts":{"impact":20.4,"likelihood":0.2,"exploitation":0,"ransomware":0},"changes":[]}